commit | 850fd984e5f346645b5a941ed7307387c7e4c4de | [log] [tgz] |
---|---|---|
author | Ioana Alexandru <aioana@google.com> | Fri May 12 15:41:09 2023 +0000 |
committer | Ioana Alexandru <aioana@google.com> | Tue May 23 13:29:27 2023 +0000 |
tree | 7b45306401ec864cd5a4c52d0df6ed92826b22f0 | |
parent | 71e7d4129dcee66f4a2f5b3f4849bf50c61259d2 [diff] |
Implement visitUris for RemoteViews ViewGroupActionAdd. This is to prevent a vulnerability where notifications can show resources belonging to other users, since the URI in the nested views was not being checked. Bug: 277740082 Test: atest RemoteViewsTest NotificationVisitUrisTest Change-Id: I5c71f0bad0a6f6361eb5ceffe8d1e47e936d78f8 Merged-In: I5c71f0bad0a6f6361eb5ceffe8d1e47e936d78f8